easyMultiple Choice
CISSP Practice Question: Is conducting a security assessment of a new web…
An organization is conducting a security assessment of a new web application. Which testing technique would best identify cross-site scripting (XSS) vulnerabilities?
⚠ Common exam trap
Candidates often confuse SAST and DAST. Remember that SAST requires access to the source code (white-box) and is performed early in the SDLC, whereas DAST is performed on a running application (black-box) without requiring source code access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Dynamic application security testing (DAST)
Dynamic Application Security Testing (DAST) is a black-box testing methodology that inspects a running application from the outside in. Because the assessment is conducted without access to the source code (black-box), DAST is the primary method used to find vulnerabilities like XSS and SQL injection by actively injecting payloads into input fields and analyzing the application's runtime responses.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Manual code review
Why it's wrong here
While thorough for specific code sections, manual code review is inherently time-consuming and prone to human oversight, especially in large or complex applications. It struggles to identify vulnerabilities that manifest only during runtime interaction, such as intricate cross-site scripting (XSS) payloads or complex injection logic that requires dynamic execution to trigger. Its effectiveness is limited by the reviewer's expertise and the sheer volume of code.
- ✗
Static application security testing (SAST)
Why it's wrong here
Static Application Security Testing (SAST) tools analyze an application's source code, bytecode, or binaries without executing the program. While effective at finding common coding errors and some architectural flaws, SAST often struggles to detect vulnerabilities like XSS that depend on user input, server-side processing, and client-side rendering during actual runtime. It lacks the context of how data flows and interacts dynamically, leading to potential misses for injection points that only manifest during live execution.
- ✗
Interactive application security testing (IAST)
Why it's wrong here
Interactive Application Security Testing (IAST) operates by instrumenting the application's code and observing its behavior from *within* the running environment, combining aspects of SAST and DAST. While it offers excellent visibility into data flow and vulnerability context, IAST typically requires access to the application's internal components or source code for instrumentation. This makes it less suitable for black-box, external security assessments where only the exposed interfaces are available, and the focus is on simulating real-world attacker interactions without internal access.
- ✓
Dynamic application security testing (DAST)
Why this is correct
Dynamic Application Security Testing (DAST) actively tests the running application from an external perspective, simulating real-world attacks against the deployed environment. By interacting with the application's exposed interfaces (like a browser or API client), DAST can effectively identify runtime vulnerabilities such as XSS, SQL injection, and broken authentication by observing the application's responses to malicious inputs. This black-box approach accurately reflects an attacker's view and confirms actual exploitability, making it highly effective for web application security assessments.
Go deeper
Related to this question
Learn chapter
Identity and Access Management (IAM)
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Security assessment
A security assessment is a systematic evaluation of an organization’s systems, networks, and applications to identify vulnerabilities, threats, and risks, and to recommend improvements.
About these practice questions
Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.